Egnyte CMMC Compliance: What EgnyteGov Covers—and What Stays Your Job
By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026
Egnyte CMMC compliance starts with which Egnyte environment you use. No subscription gives your company a CMMC status. For controlled unclassified information (CUI), Egnyte markets EgnyteGov and says a FedRAMP-recognized third-party assessor found it equivalent to FedRAMP Moderate in 2025. We found no comparable public claim for its commercial plans, and EgnyteGov's official listing still shows an agency authorization in process.
Even inside EgnyteGov, three things decide whether it works for you. First, does the evidence behind that 2025 claim hold up for the exact service you buy? Second, where does CUI go when your people download it, sync it, or co-edit it? Third, who does the work Egnyte doesn't do? The table below sorts out the first question. The machine-shop example further down shows where CUI can leave the planned boundary.
Status checked September 24, 2026: The Department's current CMMC page says Phase II was suspended on July 13, 2026 and implementation is paused in Phase I. Level 1 and Level 2 self-assessments remain active, and Level 2 still uses NIST SP 800-171 Revision 2. During the suspension, the Department's implementing memorandum permits only Level 1 (Self) and Level 2 (Self) designations and directs amendments or modifications to remove Level 2 (C3PAO) and Level 3 requirements from active solicitations and contracts. We found no replacement Phase II date or public Reform Task Force report on the Department's current CMMC pages. DFARS 252.204-7012 still applies wherever it is incorporated into your contract. November 10, 2026 was the suspended Phase II date, not a reason to rush a purchase. Current department pages use Department of War (DoW); the regulation and clauses cited below still use Department of Defense (DoD). See the current CMMC program status.
This guide is for you if your company uses Egnyte or is weighing it, and you handle CUI or may soon.
Three quick checks before you read on:
- Does your solicitation, contract, or a prime's flow-down include DFARS 252.204-7012?
- Does the information involved meet a CUI category or contract definition, whether or not every file is marked correctly?
- Is your company's Egnyte domain an EgnyteGov domain?
If any answer is "I don't know," start there. Your solicitation, contract, flow-down, the authorized source of the information, and applicable CUI markings or categories set the answer. A missing banner does not automatically make information Federal Contract Information (FCI). Our guide to FCI versus CUI shows where to look, and our guide to CUI markings explains what markings can—and cannot—settle.
Not for you if you have confirmed that you handle only FCI and your requirement is Level 1. Start with the Level 1 self-assessment checklist instead.
Looking for Ignyte? That's a different company with a similar name. See our Ignyte profile.
Short on time? Jump to the 12-check buyer worksheet.

Which Egnyte are you on?
Egnyte sells separate commercial and government environments, and the public federal-cloud claim examined here applies to EgnyteGov. We found no comparable FedRAMP authorization or Moderate-equivalency claim for Egnyte's commercial plans in the public Egnyte pages reviewed for this guide.
The claim in question is about the Federal Risk and Authorization Management Program (FedRAMP), the government's cloud-security assessment and authorization program. For a cloud service that stores, processes, or transmits covered defense information, DFARS 252.204-7012 requires security equivalent to the FedRAMP Moderate baseline and support for the clause's incident obligations.
| Egnyte product | What it is | Public cloud-security record checked September 24, 2026 | What that means for CUI |
|---|---|---|---|
| Commercial Egnyte (Business, Enterprise Lite, Elite, Ultimate) | Egnyte's standard cloud file platform. Its pricing page listed Business at $22, Enterprise Lite at $39, and Elite at $48 per user per month billed annually; Ultimate was quote-only. | We found no FedRAMP authorization or Moderate-equivalency claim for these commercial plans. The pricing page lists HIPAA, FINRA, SOC 2, and ISO/IEC 27001 for commercial compliant storage. | Do not borrow EgnyteGov's evidence for a commercial domain. If the commercial service stores, processes, or transmits covered defense information, the exact offering still has to satisfy DFARS 252.204-7012(b)(2)(ii)(D). |
| EgnyteGov | Egnyte's government environment. Egnyte says it runs on Google Cloud. | Marketplace status: Agency Auth In Process, with zero ATO/ATU authorizations. Egnyte announced FedRAMP Moderate equivalency on July 22, 2025. | It may support CUI through the DoD equivalency route if the current body of evidence satisfies DoD policy and covers the exact service, features, and terms you plan to use. |
| EgnyteGov Enterprise | EgnyteGov plus content discovery and labeling that can scan other repositories, according to Egnyte. Egnyte's help center identifies EgnyteGov and EgnyteGov Enterprise as its two CUI offerings. | Same EgnyteGov Marketplace record and company-stated equivalency route. | Confirm which repositories its connectors read, what data or metadata they send, where results live, and whether each feature is inside the assessed offering. |
| Compliance Center and Compliance Agent | Tools that, according to Egnyte, collect compliance artifacts and turn raw artifacts into assessment-ready responses. | Not a FedRAMP authorization and not a CMMC status. | They can organize evidence. Their public description does not establish your implementation, assessment result, SPRS submission, or affirmation. |
Think of commercial Egnyte and EgnyteGov as two buildings run by the same landlord. The federal-cloud evidence Egnyte cites applies to the second building. A commercial-domain customer cannot borrow that evidence for the first.
Not sure which you have? Ask your Egnyte administrator whether your company has a separate EgnyteGov domain. Egnyte's engineering blog says many customers run domains in both environments. That can work only when your data flows, endpoints, identities, and integrations keep CUI inside the approved boundary you document.
Your next step may not be a product at all. It could be a CUI enclave like EgnyteGov, which is a walled-off space where CUI work happens. It could be a broader government cloud, a managed security provider to run controls, or readiness help from a Registered Practitioner Organization (RPO). Which one fits depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT setup, and your contract timeline. The solicitation, contract, or flow-down sets the required level and status—not a checklist. Because a general answer cannot settle those questions for you, use The Defense Compliance Report's Find My CMMC Path tool to identify the kind of help to evaluate before you request quotes. Do not submit CUI, drawings, or sensitive contract details.
If CUI is real for you, the next question isn't simply "which product." It's whether your gap is a controlled place for files, help getting ready, or someone to run the environment day to day. Your contract, your data flow, and your team decide that.
Is EgnyteGov FedRAMP authorized?
Not as of September 24, 2026. EgnyteGov's official FedRAMP Marketplace record shows an agency authorization in process, with no Authority to Operate or Authority to Use authorizations issued. For CUI, Egnyte relies on a separate DoD route called FedRAMP Moderate equivalency, and that route is supported by a nonpublic evidence package—not by the in-process listing alone.
Here is the record as we read it:
| Field | EgnyteGov on the FedRAMP Marketplace |
|---|---|
| Package ID | FR2024952734 |
| Provider | Egnyte, Inc. |
| Status | Agency Auth In Process (as of September 22, 2026) |
| Phase | Initial Implementation |
| Authorizations shown | 0 |
| Certification profile | Rev5 · Agency path · Class C (Moderate) |
| Certified since | N/A |
| We checked | September 24, 2026 |
Source: FedRAMP Marketplace record FR2024952734.
What the fields mean. The Marketplace uses "FedRAMP Certified" for its finished lifecycle status and separately reports Authority to Operate and Authority to Use authorizations. "Agency Auth In Process" means the offering is pursuing an agency path; it is not in the finished certified status. "Certified since: N/A" and zero authorizations confirm that distinction. Class C is the Marketplace's current Moderate profile label.
Why that isn't the end of the story. The CMMC rule gives a cloud service holding CUI two routes under 32 CFR 170.16(c)(2):
- The specific product or service offering can be FedRAMP Authorized at Moderate or higher on the Marketplace.
- If it is not authorized, the specific offering can meet security requirements equivalent to that baseline in accordance with DoD policy.
An in-process listing is neither route on its own. EgnyteGov's current public case for CUI therefore rests on the company-stated equivalency route and the supporting evidence your company reviews.
The equivalency standard. A December 21, 2023 DoD CIO memorandum states that an equivalent cloud service offering must:
- Achieve 100 percent compliance with the latest FedRAMP Moderate security-control baseline.
- Be assessed by a FedRAMP-recognized Third-Party Assessment Organization (3PAO). A FedRAMP 3PAO assesses cloud offerings; it is not the same as a CMMC Third-Party Assessment Organization (C3PAO), which conducts CMMC certification assessments.
- Present a body of evidence to the contractor.
The memo does not confer a FedRAMP authorization. It puts the onus on the contractor to validate the body of evidence for the cloud offering it plans to use.
What Egnyte says about its evidence. Egnyte attributes several points about the package to itself:
- Its 3PAO issued a "letter of attestation" after assessing EgnyteGov, backed by a Security Assessment Report and a risk exposure table, according to Egnyte.
- EgnyteGov customers can see "many components" of the evidence package under a non-disclosure agreement (NDA), according to Egnyte's July 30, 2025 post.
- A 3PAO reviews one-third of the controls each year and conducts a full reassessment every three years, according to the same Egnyte post.
One more note: Egnyte's announcement said the Marketplace listing makes its designation easy to verify. The official listing verifies the agency-authorization process and its current status. It does not display or validate the private DoD-equivalency package.
The honest limit. We have not seen Egnyte's evidence package, and it is not public. Egnyte says customers can review many components under NDA. That means someone qualified on your side still has to read what is provided, connect it to the exact service you are buying, and document unresolved gaps. Here is what to ask for.
What to ask for when a provider relies on equivalency
Ask for the package behind the claim, not another badge or sales slide. Your reviewer needs to connect the assessed cloud-service boundary to the exact EgnyteGov services and features you plan to use.
| Document or evidence | What to check |
|---|---|
| System Security Plan (SSP) for the cloud service | The service boundary matches what you are buying, and provider, shared, and customer responsibilities are clear. |
| Security Assessment Plan (SAP) | A FedRAMP-recognized 3PAO performed the work; the plan states what was tested, when, and with which procedures. |
| Security Assessment Report (SAR), including the Risk Exposure Table | Findings, test results, report date, scope, and closure evidence. |
| Plan of Action and Milestones (POA&M) and continuous-monitoring material | Assessment-derived actions were corrected and validated as closed; any operational POA&Ms are clearly distinguished and current. |
| Customer Responsibility Matrix (CRM) | Which requirements are Egnyte's, which are shared, and which your company must implement and document. |
| Current annual 3PAO assessment or validation evidence | The latest recurring review covers the offering and contractual incident obligations on which you intend to rely. |
One nuance matters when you read the POA&M. The DoD memorandum itself says POA&M actions resulting from the 3PAO equivalency assessment must be corrected and validated as closed. It also allows operational POA&Ms that did not result from that assessment. Do not shorten that to "no POA&Ms," and do not confuse either category with the separate limited POA&M rules for your own CMMC status.
Does buying EgnyteGov make your company CMMC compliant?
No. A CMMC status belongs to your organization and its defined assessment scope, not to a software vendor. EgnyteGov can be one documented part of that environment, but your implementation, devices, people, procedures, evidence, and connections remain part of the answer.
The rule is specific. Under 32 CFR 170.16(c)(2)(iii), your infrastructure connecting to the cloud offering is part of the assessment scope. The cloud provider's customer responsibilities must be documented or referenced in your SSP. Section 170.19(c)(2) also requires the service relationship, service description, CRM, and assessment treatment to line up.
Egnyte's marketing uses stronger words than the rules do. Here is what several statements mean for a buyer.
| What Egnyte says | What it means for you |
|---|---|
| EgnyteGov is an "isolated, CMMC-compliant environment" on its CMMC product page. | The offering may support a compliant scoped environment. Your company still earns and maintains its own CMMC status for the scope it defines and operates. |
| The same page describes equivalency as "the certification" that a provider meets the controls. | Moderate equivalency is a DoD acceptance route backed by evidence. It is not a FedRAMP certification, and the Marketplace does not display it. |
| Working with a qualified provider "reduces assessment scope." | A contained architecture can reduce scope, but the result follows the asset categories and data flows in 32 CFR 170.19—not the product label. CUI assets, security-protection assets, contractor risk-managed assets, specialized assets, and a true VDI exception receive different treatment. |
| Compliance Center maps all 110 Level 2 requirements. | A map can organize work and evidence. Your organization still has to implement the applicable requirements and satisfy the NIST SP 800-171A assessment objectives. |
| Existing customers' C3PAOs found Egnyte's documentation satisfied their assessments, according to Egnyte. | That is a company-stated experience from other assessments. Obtain the current package and have it reviewed for your exact scope and assessment path. |
| A customer card says one firm "achieved CMMC Level 2 compliance" on the product page. | The linked case study describes the firm as having met roughly 90 percent of requirements and working toward full compliance. Neither public page gives an assessment type, CMMC Status Date, or official result. Do not use the card as evidence for your environment. |
| Egnyte's compliance standards page says NIST SP 800-171 requirements are met "by implementing the ISO27001 controls." | A crosswalk is not a substitute for implementing Revision 2 and satisfying its assessment objectives. For a cloud service holding CUI, the separate FedRAMP Moderate authorization-or-equivalency rule also applies. The page still frames CMMC through the December 2023 proposed rule, so check dates on vendor pages. |
What stays your job
These duties come from the governing requirements, not from Egnyte:
- Describe EgnyteGov in your SSP and map its CRM into your implementation (§170.16(c)(2)(iii), §170.19(c)(2)).
- Require and ensure that the cloud provider meets the applicable cloud and incident obligations. That is the contractor's wording in DFARS 252.204-7012(b)(2)(ii)(D).
- When Level 2 (Self) is required, assess your organization against the 110 requirements in NIST SP 800-171 Revision 2 using NIST SP 800-171A June 2018 and the CMMC Scoring Methodology. Submit the required result in the Supplier Performance Risk System (SPRS), reassess every three years, and have an Affirming Official affirm at each assessment and annually thereafter. The current rule has not switched CMMC Level 2 to Revision 3. Our SPRS guide and annual affirmation guide cover those neighboring tasks.
- Treat a Level 2 POA&M as a limited, time-bound status—not a blanket permission to defer controls. If the conditions in 32 CFR 170.21 are met, a Conditional Level 2 (Self) status can use a POA&M that must be closed within 180 days. SPRS records the overall score and POA&M status.
- Report covered cyber incidents when DFARS 252.204-7012 applies. The contractor reports to DoD within 72 hours through DIBNet and needs a DoD-approved medium-assurance certificate. See our DFARS 252.204-7012 guide.
- Keep the assessment evidence for six years from the CMMC Status Date (§170.16(c)(4)).
- Own or contract for the controls outside Egnyte. That can include endpoints, identity, email, training, physical protection, monitoring, incident response, and the people who operate them.
What stays in scope when your team uses Egnyte?
Follow the information, not the logo. A drawing downloaded into local design software is still on that workstation, even if the original lives in EgnyteGov. Convenience features can add devices and services to your scope—or create a risk-managed or specialized-asset treatment that has to be documented correctly.
The rule sorts Level 2 assets into categories under 32 CFR 170.19(c)(1), Table 3:
- CUI Assets process, store, or transmit CUI and are assessed against all Level 2 requirements.
- Security Protection Assets provide security functions or capabilities to the assessment scope and are assessed against requirements relevant to those capabilities.
- Contractor Risk Managed Assets can, but are not intended to, process, store, or transmit CUI because of documented policies, procedures, and practices. They remain in scope and can receive a limited check.
- Specialized Assets include certain Internet of Things, operational technology, government-furnished equipment, restricted systems, and test equipment. They are documented and managed through the contractor's risk-based approach rather than treated like ordinary office endpoints.
- Out-of-Scope Assets cannot process, store, or transmit CUI and are physically or logically separated from CUI assets, except for the rule's narrow virtual-desktop condition.
So "we don't intend to store CUI there" does not make a laptop out of scope by itself.
Here is how common Egnyte workflows change the analysis. Our read is this publication's framework built from the scoping rule and the provider's public documentation. It is not an assessment result.
| Egnyte workflow | What can happen to the data flow | Our read | Before CUI goes through it |
|---|---|---|---|
| Uploading and downloading in a browser | A downloaded copy lands on the endpoint. | If the endpoint processes or stores CUI, treat it as a CUI asset unless a specific rule-based treatment applies. | Use managed endpoints, document them in the SSP and inventory, and control local copies. |
| Egnyte Desktop App, sync, or cloud drive | Local caching or sync can put CUI on each configured device. | In scope when CUI is processed or stored there. | Confirm cache behavior; apply inventory, access, encryption, patching, and evidence requirements. |
| Smart Cache or another on-site cache | The appliance can hold local copies of files. | If it stores CUI, it is part of the CUI environment. | Confirm in writing that the feature is available for the quoted EgnyteGov service and document the appliance, admins, backups, and data flow. |
| Mobile apps | Phones and tablets can process or store CUI. | A managed or personally owned label does not decide scope; actual capability and use do. | Permit only devices that meet your documented controls and mobile policy. See our mobile-device guide. |
| Sharing with outside users | CUI can reach another company's people and devices. | Recipient authorization, the other environment, and contractual flow-down can all matter. | Use named, expiring access; prohibit open links; and flow DFARS 252.204-7012 when paragraph (m) applies because subcontract performance involves covered defense information or operationally critical support. |
| Microsoft 365 for the web co-editing | Egnyte's Microsoft 365 FAQ says Microsoft caches files opened this way and users may be routed to global data centers. The article does not establish EgnyteGov availability. | Keep CUI out until the exact EgnyteGov and Microsoft boundary is documented. | Get a written answer covering availability, caching, location, identity, logs, and the applicable Microsoft service. |
| Opening files in desktop Word, Excel, CAD, or other local software | The endpoint processes CUI and may create temporary or recovery files. | In scope according to its asset category and actual behavior. | Verify local storage, autosave, temp files, crash recovery, print, and any commercial-cloud synchronization. |
| Google Workspace co-editing | A second cloud service may process or cache the content. | Keep CUI out until the exact service path and cloud evidence are documented. | Get the boundary, FedRAMP/equivalency route where applicable, CRM, locations, logs, and deletion behavior in writing. |
| Outlook add-in or filing email into Egnyte | CUI may pass through or remain in the email system. | A file platform does not make an ordinary email environment suitable for CUI. | Document whether CUI enters email, where copies remain, and which service is the approved system of record. |
| Artificial-intelligence features on CUI folders | Search, assistants, or agents may process content, metadata, prompts, or outputs. | Leave the feature off for CUI until the exact assessed boundary and data-handling terms are confirmed. | Ask about model providers, retention, training, subprocessors, locations, logs, output storage, and whether the feature is included in the body of evidence. |
| Customer-supplied storage or data-residency options | A separate storage account or service can hold CUI. | Evaluate the exact storage offering under the cloud and scoping rules; the application vendor's status does not automatically cover it. | Request the exact architecture, authorization or equivalency evidence, CRM, key ownership, logging, and incident terms. |
| Third-party integrations and application programming interfaces (APIs) | CUI, metadata, credentials, or security-protection data may cross the planned boundary. | Keep CUI out until each integration's data path and role are documented. | Confirm which integrations are available in EgnyteGov, what each reads or writes, where it runs, and which provider responsibilities apply. |
A machine-shop example
Test your plan with a made-up drawing before any real CUI goes in. What you want to end up with is a list of places and owners, not a headcount.
Say a 30-person machine shop has six employees who work with controlled drawings. Its engineers download files into local computer-aided design (CAD) software. The shop is weighing a quote labeled "EgnyteGov plus CMMC add-on." The shop, its numbers, and its findings are fictional.
| Worksheet item | Fictional finding | Next step |
|---|---|---|
| Exact purchase | The quote names EgnyteGov, but the features and services are not itemized. | Ask for the feature and service schedule. |
| Cloud evidence | The team read the Marketplace record, not the private equivalency package. | Request controlled access to the package under NDA and assign a qualified reviewer. |
| Drawing workflow | Six engineers download drawings into local CAD software. | Treat those workstations according to their actual CUI processing and storage; plan the required management, encryption, and evidence. |
| On-site cache | Smart Cache runs on the shop-floor server for large files. | Keep CUI folders off the cache until Egnyte confirms the quoted service, boundary, and responsibilities in writing. |
| Backup | A third-party backup service connects to Egnyte, and its data path is not documented. | Leave it unresolved; obtain the data flow, exact offering, cloud-security route, CRM, and incident terms. |
| Outside shop | A heat-treat subcontractor needs two drawings. | Confirm the recipient and environment are authorized; flow DFARS 252.204-7012 if paragraph (m) applies; use named, expiring access. |
| Remaining work | The office manager owns the project; no setup or operating help appears in the order. | Decide who configures, documents, monitors, and maintains the remaining environment before signing. |
The result is a candidate worth evaluating further. It is not a compliant environment, and the shop is not assessment-ready. What it now has is a specific evidence request and a clear list of work, in place of a vague "Is Egnyte compliant?" The scope follows where the drawings and supporting security functions actually go, not the employee count.
Three questions Egnyte's public pages don't answer
In the public Egnyte pages reviewed for this guide, we did not find complete answers to three questions that matter for defense work: who can reach customer data, which validated cryptographic modules cover the exact deployment, and what Egnyte will commit to during a DFARS cyber incident. That does not establish that Egnyte falls short. It means the answer belongs in your evidence package or contract, not in an assumption.
Who can reach your data?
Egnyte's engineering blog says the company did not create a dedicated staff to operate EgnyteGov and that engineers work across its commercial and government environments (Egnyte blog, August 15, 2025). That statement does not establish who can access a customer's files. We found no public statement in the reviewed pages saying that administrative, support, and engineering access to EgnyteGov customer data is limited to U.S. persons.
This matters when your information is subject to the International Traffic in Arms Regulations (ITAR), the Export Administration Regulations (EAR), or another access restriction. The Bureau of Industry and Security says releasing controlled technology to a foreign person in the United States can be a deemed export; whether authorization is required depends on the technology, the person, and the applicable authorization or exception. ITAR and contract restrictions have their own rules. A FedRAMP record does not settle those questions. Ask Egnyte in writing about administrative, support, and engineering access; subprocessors; storage and support locations; and access logging. Have your export-compliance lead or counsel resolve the rule that applies to your data. Our guide for ITAR companies covers the CMMC side.
Which validated encryption protects it?
NIST SP 800-171 Revision 2 requirement 3.13.11 requires FIPS-validated cryptography when cryptography is used to protect the confidentiality of CUI. Egnyte says EgnyteGov uses "FIPS 140-validated cryptographic modules" (Egnyte, July 30, 2025), but we found no certificate numbers in the reviewed public pages.
The timing changed before this page was published. NIST's schedule placed all FIPS 140-2 certificates on the Historical List on September 22, 2026. Historical does not mean revoked: NIST says it still supports purchase and use of those modules for existing systems. Ask Egnyte for the Cryptographic Module Validation Program (CMVP) certificate numbers, module names, versions, operational environments, and configurations covering data at rest and in transit. For each one, record whether it is FIPS 140-3 Active or FIPS 140-2 Historical and how it maps to your deployed service. Our FIPS 140 guide explains how to check the evidence.
What happens during an incident?
The DFARS cloud sentence has two halves joined by "and." The cloud service must meet security equivalent to FedRAMP Moderate, and the provider must comply with paragraphs (c) through (g) of DFARS 252.204-7012. Egnyte's public pages address the security-baseline side. We found no public Egnyte commitment covering the complete (c)-through-(g) support chain.
| Paragraph | What the clause requires | What to ask Egnyte |
|---|---|---|
| (c) Incident reporting | The contractor reviews for compromise and reports a covered cyber incident to DoD within 72 hours of discovery. | How quickly will Egnyte notify us, through which channel, and with what information so we can meet our reporting duty? |
| (d) Malicious software | When malicious software is discovered and isolated in connection with a reported incident, it is submitted to the DoD Cyber Crime Center under its instructions. | Will Egnyte preserve and provide isolated malicious software connected to our tenant or incident? |
| (e) Media preservation | Preserve images of known affected systems and relevant monitoring or packet-capture data for at least 90 days after the report. | What tenant-specific images, logs, and packet data can Egnyte preserve, and how do we trigger preservation? |
| (f) Forensic access | Provide DoD access to additional information or equipment needed for forensic analysis when requested. | What is Egnyte's process for supporting a DoD forensic request while protecting other tenants? |
| (g) Damage assessment | Provide requested damage-assessment information gathered under the preservation requirement. | What can Egnyte provide, who coordinates it, and what contractual limits apply? |
Your reporting duty stays yours. The DoD equivalency memorandum says the contractor—not the cloud provider—is responsible for reporting a compromise, while the contractor must ensure the provider follows its incident-response plan and can notify the contractor.
The Egnyte CMMC compliance buyer worksheet
Use these 12 checks to turn a sales conversation into a documented decision. For each check, record who owns it, what you asked for, what you reviewed, and what is still open. "Reviewed" means someone read the material. It does not mean your company passed CMMC.
The 12 checks are this publication's buying method. They are not an official government checklist, and 12 is not the number of CMMC requirements.
| # | Check | Ask Egnyte for | What your company decides | Basis |
|---|---|---|---|---|
| 1 | Exact purchase | The exact offering name, confirmation that the CUI domain is EgnyteGov, included services and add-ons, exclusions, term, and service boundary in writing. | Does the order match the service and features you evaluated? | The cloud rule applies to the specific product or service offering: §170.16(c)(2). |
| 2 | Cloud-security route | Which route covers that exact offering: a FedRAMP Moderate-or-higher authorization or the DoD Moderate-equivalency route. | Do not accept an in-process listing, an underlying cloud provider's status, or another product's status as the answer. | §170.16(c)(2)(i)-(ii); DFARS 252.204-7012(b)(2)(ii)(D). |
| 3 | Equivalency package | SSP, SAP, SAR and Risk Exposure Table, assessment-derived closure evidence, continuous-monitoring material, the FedRAMP-recognized 3PAO's name, assessment dates, and current annual 3PAO validation evidence under NDA. | Who reviews the package, whether the boundary matches, and which questions remain unresolved. | DoD CIO FedRAMP Moderate Equivalency memorandum, December 21, 2023. |
| 4 | Responsibility matrix | The current CRM for every service and feature in the order. | An owner for every provider, shared, and customer responsibility; the responsibilities reflected in your SSP. | §170.16(c)(2)(iii); §170.19(c)(2). |
| 5 | Live demo with fake files | Show user access, multi-factor authentication (MFA), outside sharing, admin access, access removal, and audit export. Then walk a fictional drawing through open, edit, download, sync, cache, print, backup, and deletion. | Who approves access and which devices, services, people, and records enter the CUI environment. | NIST SP 800-171 Rev. 2 requirements 3.1.1, 3.1.2, 3.5.3; §170.19(c)(1). |
| 6 | Features and connections | A written boundary and data-flow answer for each feature you plan to use: desktop app, cache, mobile, co-editing, Outlook, AI, connectors, APIs, backups, and customer-supplied storage. | Which features are permitted in the CUI workflow and what evidence each needs. | NIST SP 800-171 Rev. 2 requirement 3.1.3; DFARS cloud rule; §170.19. |
| 7 | Evidence versus labels | One worked example: a configuration, the artifact it produces, the assessment objective it supports, and which evidence your company still supplies. | Whether "mapped" or AI-generated items are backed by real implementation evidence. | NIST SP 800-171A June 2018, incorporated by 32 CFR Part 170. |
| 8 | Encryption certificates | CMVP certificate numbers, module names, versions, operational environments, configurations, and status for cryptography protecting data at rest and in transit. | Whether the exact deployed modules support requirement 3.13.11; a product name or algorithm is not enough. | NIST SP 800-171 Rev. 2 requirement 3.13.11; NIST CMVP transition guidance. |
| 9 | Incident support | Written commitments covering DFARS 252.204-7012 paragraphs (c) through (g), including notice, preservation, malware, forensic, and damage-assessment support. | How your 72-hour reporting process works with Egnyte's notice and evidence. | DFARS 252.204-7012(b)(2)(ii)(D), (c)-(g); DoD equivalency memorandum. |
| 10 | Who can reach the data | Access-eligibility rules for administrators, support, engineering, and subprocessors; storage and support locations; access logs; and key-management roles. | Whether the answer fits the CUI category and any export-control or contract restriction that applies to your data. | Your contract, export-control analysis, SSP, and data flow. |
| 11 | Work outside the subscription | A written split of endpoint management, identity, email, training, monitoring, incident response, SSP maintenance, and evidence operations: what Egnyte does, what is bundled, and what remains yours. | Who owns each remaining task: internal staff, another provider, or genuinely included work. | Your assessment boundary, CRM, SSP, and service order. |
| 12 | Exit and records | Export formats, access after cancellation, deletion terms, transition assistance, retained-access period, and all charges. | How you retain required assessment artifacts and operational records without depending on an expired subscription. | §170.16(c)(4); your contract and quote. |
How to fill it in
Leave an unanswered item as Unknown or Requested. Do not count missing evidence as a successful check. Every check starts at Unknown.
| Status | What it means |
|---|---|
| Unknown | Nobody has asked or answered yet. This is the default. |
| Requested | You asked Egnyte or your team, and you are waiting. |
| Reviewed | Someone qualified read the material. This is not a CMMC determination. |
| Not applicable | Allowed only with a written reason. |
At the top of the worksheet, record three setup facts: your required CMMC level and assessment type—or Unknown; the information involved—FCI only, CUI, or Unknown; and the exact offering and add-ons quoted. For each check, record these fields:
| Field | What to write |
|---|---|
| Status | Unknown, Requested, Reviewed, or Not applicable. |
| Owner | A role, such as IT lead, security lead, contracts manager, or office manager. |
| Evidence requested | What you asked for and from whom. |
| Evidence reference and review date | Where the evidence lives in your approved systems and when it was reviewed. |
| Unresolved issue | What is still open. |
| Next action | Who does what next and by when. |
| Reason, if not applicable | Required whenever a check is marked Not applicable. |
Egnyte CMMC Buyer Worksheet — Source version: September 24, 2026 — The Defense Compliance Report
SETUP
Required CMMC level / assessment type (Known: ____ / Unknown):
Information involved (FCI only / CUI / Unknown):
Exact offering and add-ons quoted: ____
12 CHECKS
1. Exact purchase
Ask Egnyte for: The exact offering name, confirmation that the CUI domain is EgnyteGov, included services and add-ons, exclusions, term, and service boundary in writing.
What your company decides: Does the order match the service and features you evaluated?
Basis: The cloud rule applies to the specific product or service offering: §170.16(c)(2).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
2. Cloud-security route
Ask Egnyte for: Which route covers that exact offering: a FedRAMP Moderate-or-higher authorization or the DoD Moderate-equivalency route.
What your company decides: Do not accept an in-process listing, an underlying cloud provider's status, or another product's status as the answer.
Basis: §170.16(c)(2)(i)-(ii); DFARS 252.204-7012(b)(2)(ii)(D).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
3. Equivalency package
Ask Egnyte for: SSP, SAP, SAR and Risk Exposure Table, assessment-derived closure evidence, continuous-monitoring material, the FedRAMP-recognized 3PAO's name, assessment dates, and current annual 3PAO validation evidence under NDA.
What your company decides: Who reviews the package, whether the boundary matches, and which questions remain unresolved.
Basis: DoD CIO FedRAMP Moderate Equivalency memorandum, December 21, 2023.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
4. Responsibility matrix
Ask Egnyte for: The current CRM for every service and feature in the order.
What your company decides: An owner for every provider, shared, and customer responsibility; the responsibilities reflected in your SSP.
Basis: §170.16(c)(2)(iii); §170.19(c)(2).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
5. Live demo with fake files
Ask Egnyte for: Show user access, multi-factor authentication (MFA), outside sharing, admin access, access removal, and audit export. Then walk a fictional drawing through open, edit, download, sync, cache, print, backup, and deletion.
What your company decides: Who approves access and which devices, services, people, and records enter the CUI environment.
Basis: NIST SP 800-171 Rev. 2 requirements 3.1.1, 3.1.2, 3.5.3; §170.19(c)(1).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
6. Features and connections
Ask Egnyte for: A written boundary and data-flow answer for each feature you plan to use: desktop app, cache, mobile, co-editing, Outlook, AI, connectors, APIs, backups, and customer-supplied storage.
What your company decides: Which features are permitted in the CUI workflow and what evidence each needs.
Basis: NIST SP 800-171 Rev. 2 requirement 3.1.3; DFARS cloud rule; §170.19.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
7. Evidence versus labels
Ask Egnyte for: One worked example: a configuration, the artifact it produces, the assessment objective it supports, and which evidence your company still supplies.
What your company decides: Whether "mapped" or AI-generated items are backed by real implementation evidence.
Basis: NIST SP 800-171A June 2018, incorporated by 32 CFR Part 170.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
8. Encryption certificates
Ask Egnyte for: CMVP certificate numbers, module names, versions, operational environments, configurations, and status for cryptography protecting data at rest and in transit.
What your company decides: Whether the exact deployed modules support requirement 3.13.11; a product name or algorithm is not enough.
Basis: NIST SP 800-171 Rev. 2 requirement 3.13.11; NIST CMVP transition guidance.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
9. Incident support
Ask Egnyte for: Written commitments covering DFARS 252.204-7012 paragraphs (c) through (g), including notice, preservation, malware, forensic, and damage-assessment support.
What your company decides: How your 72-hour reporting process works with Egnyte's notice and evidence.
Basis: DFARS 252.204-7012(b)(2)(ii)(D), (c)-(g); DoD equivalency memorandum.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
10. Who can reach the data
Ask Egnyte for: Access-eligibility rules for administrators, support, engineering, and subprocessors; storage and support locations; access logs; and key-management roles.
What your company decides: Whether the answer fits the CUI category and any export-control or contract restriction that applies to your data.
Basis: Your contract, export-control analysis, SSP, and data flow.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
11. Work outside the subscription
Ask Egnyte for: A written split of endpoint management, identity, email, training, monitoring, incident response, SSP maintenance, and evidence operations: what Egnyte does, what is bundled, and what remains yours.
What your company decides: Who owns each remaining task: internal staff, another provider, or genuinely included work.
Basis: Your assessment boundary, CRM, SSP, and service order.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
12. Exit and records
Ask Egnyte for: Export formats, access after cancellation, deletion terms, transition assistance, retained-access period, and all charges.
What your company decides: How you retain required assessment artifacts and operational records without depending on an expired subscription.
Basis: §170.16(c)(4); your contract and quote.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
STATUS DEFINITIONS
Unknown | Nobody has asked or answered yet. This is the default.
Requested | You asked Egnyte or your team, and you are waiting.
Reviewed | Someone qualified read the material. This is not a CMMC determination.
Not applicable | Allowed only with a written reason.
WARNINGS
Keep evidence in your company's approved systems.
Do not place CUI, drawings, credentials, or sensitive contract details in this worksheet.
'Reviewed' is not a CMMC determination.
SOURCES
- FedRAMP Marketplace, "EgnyteGov," package FR2024952734 — https://www.fedramp.gov/marketplace/products/FR2024952734/ (checked September 24, 2026)
- 32 CFR 170.16, Level 2 self-assessment, SPRS, affirmation, cloud, and artifact-retention requirements — https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.16 (checked September 24, 2026; eCFR displayed current through September 23, 2026)
- 32 CFR 170.19, CMMC scoping, Level 2 asset categories, CSP/ESP treatment, and VDI condition — https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.19 (checked September 24, 2026)
- DFARS 252.204-7012 (MAY 2024), paragraphs (b)(2)(ii)(D), (c)-(g), and (m) — https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. (checked September 24, 2026)
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems — https://www.acquisition.gov/far/52.204-21 (checked September 24, 2026)
- DoW CIO, "About CMMC" — https://dowcio.war.gov/CMMC/About/ (checked September 24, 2026)
- Under Secretary of War for Acquisition and Sustainment, "Implementing Department of War Chief Information Officer's Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements," memorandum 26-P-1023 and Attachment 1, July 13, 2026 — https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf (read in full September 24, 2026)
- Defense Acquisition Regulations System, DFARS Revolutionary FAR Overhaul Class Deviations — https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html (index checked September 24, 2026; listed 2026-O0025 Revision 3 dated September 3, 2026; attachment not represented as read)
- DoD CIO, "FedRAMP Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings," December 21, 2023 — https://dowcio.war.gov/Portals/0/Documents/Library/FEDRAMP-EquivalencyCloudServiceProviders.pdf (read in full September 24, 2026)
- NIST SP 800-171 Revision 2, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations" — https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final (checked September 24, 2026; CMMC applicability verified against 32 CFR Part 170)
- NIST SP 800-171A June 2018, "Assessing Security Requirements for Controlled Unclassified Information" — https://csrc.nist.gov/pubs/sp/800/171/a/final (checked September 24, 2026; CMMC applicability verified against 32 CFR 170.16)
- NIST CMVP, FIPS 140-3 Transition Effort — https://csrc.nist.gov/projects/fips-140-3-transition-effort (checked September 24, 2026)
- U.S. Department of Commerce, Bureau of Industry and Security, "What is a deemed export?" — https://www.bis.gov/learn-support/deemed-exports/what-deemed-export (checked September 24, 2026)
- Egnyte, "Egnyte Achieves FedRAMP Moderate Equivalency and Marketplace Listing," July 22, 2025 — https://www.egnyte.com/press-releases/egnyte-achieves-fedramp-moderate-equivalency-and-marketplace-listing-strengthening-secure-cloud-collaboration-for-the-public-sector (checked September 24, 2026; company statement)
- Egnyte blog, "Unlocking Enhanced Security: What Egnyte's FedRAMP Moderate Equivalency Means for You," July 30, 2025 — https://www.egnyte.com/blog/post/unlocking-enhanced-security-what-egnytes-fedramp-moderate-equivalency-means-for-you (checked September 24, 2026; company statement)
- Egnyte blog, "Egnyte's Journey to FedRAMP Compliance and Beyond," August 15, 2025 — https://www.egnyte.com/blog/post/egnytes-journey-to-fedramp-compliance-and-beyond (checked September 24, 2026; company statement)
- Egnyte, CMMC Compliance product page — https://www.egnyte.com/products/cmmc-compliance (checked September 24, 2026; company claims)
- Egnyte, Pricing — https://www.egnyte.com/pricing (checked September 24, 2026)
- Egnyte, Compliance Standards — https://www.egnyte.com/security/compliance-standards (checked September 24, 2026; company claims)
- Egnyte, AI-powered workflow automation release, August 5, 2026 — https://www.egnyte.com/press-releases/egnyte-launches-ai-powered-workflow-automation-with-built-in-governance-to-help-organizations-scale-efficiently-and-securely (checked September 24, 2026; company claims)
- Egnyte Help Center, "CMMC 2.0 Resources for DoD Contractors and Subcontractors" — https://helpdesk.egnyte.com/hc/en-us/articles/28498075928589-CMMC-2-0-Resources-for-DoD-Contractors-and-Subcontractors (checked September 24, 2026; offering names only; timing language not relied on)
- Egnyte Help Center, "Microsoft 365 FAQs" — https://helpdesk.egnyte.com/hc/en-us/articles/360026902251-Microsoft-365-FAQs (checked September 24, 2026; does not establish EgnyteGov availability)
- Egnyte, ERRG case study — https://www.egnyte.com/customers/errg-case-study (checked September 24, 2026; company-stated customer story)
Egnyte CMMC Buyer Worksheet
Egnyte CMMC Buyer Worksheet — Source version: September 24, 2026 — The Defense Compliance Report
SETUP
Required CMMC level / assessment type (Known: ____ / Unknown):
Information involved (FCI only / CUI / Unknown):
Exact offering and add-ons quoted: ____
12 CHECKS
1. Exact purchase
Ask Egnyte for: The exact offering name, confirmation that the CUI domain is EgnyteGov, included services and add-ons, exclusions, term, and service boundary in writing.
What your company decides: Does the order match the service and features you evaluated?
Basis: The cloud rule applies to the specific product or service offering: §170.16(c)(2).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
2. Cloud-security route
Ask Egnyte for: Which route covers that exact offering: a FedRAMP Moderate-or-higher authorization or the DoD Moderate-equivalency route.
What your company decides: Do not accept an in-process listing, an underlying cloud provider's status, or another product's status as the answer.
Basis: §170.16(c)(2)(i)-(ii); DFARS 252.204-7012(b)(2)(ii)(D).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
3. Equivalency package
Ask Egnyte for: SSP, SAP, SAR and Risk Exposure Table, assessment-derived closure evidence, continuous-monitoring material, the FedRAMP-recognized 3PAO's name, assessment dates, and current annual 3PAO validation evidence under NDA.
What your company decides: Who reviews the package, whether the boundary matches, and which questions remain unresolved.
Basis: DoD CIO FedRAMP Moderate Equivalency memorandum, December 21, 2023.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
4. Responsibility matrix
Ask Egnyte for: The current CRM for every service and feature in the order.
What your company decides: An owner for every provider, shared, and customer responsibility; the responsibilities reflected in your SSP.
Basis: §170.16(c)(2)(iii); §170.19(c)(2).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
5. Live demo with fake files
Ask Egnyte for: Show user access, multi-factor authentication (MFA), outside sharing, admin access, access removal, and audit export. Then walk a fictional drawing through open, edit, download, sync, cache, print, backup, and deletion.
What your company decides: Who approves access and which devices, services, people, and records enter the CUI environment.
Basis: NIST SP 800-171 Rev. 2 requirements 3.1.1, 3.1.2, 3.5.3; §170.19(c)(1).
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
6. Features and connections
Ask Egnyte for: A written boundary and data-flow answer for each feature you plan to use: desktop app, cache, mobile, co-editing, Outlook, AI, connectors, APIs, backups, and customer-supplied storage.
What your company decides: Which features are permitted in the CUI workflow and what evidence each needs.
Basis: NIST SP 800-171 Rev. 2 requirement 3.1.3; DFARS cloud rule; §170.19.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
7. Evidence versus labels
Ask Egnyte for: One worked example: a configuration, the artifact it produces, the assessment objective it supports, and which evidence your company still supplies.
What your company decides: Whether "mapped" or AI-generated items are backed by real implementation evidence.
Basis: NIST SP 800-171A June 2018, incorporated by 32 CFR Part 170.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
8. Encryption certificates
Ask Egnyte for: CMVP certificate numbers, module names, versions, operational environments, configurations, and status for cryptography protecting data at rest and in transit.
What your company decides: Whether the exact deployed modules support requirement 3.13.11; a product name or algorithm is not enough.
Basis: NIST SP 800-171 Rev. 2 requirement 3.13.11; NIST CMVP transition guidance.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
9. Incident support
Ask Egnyte for: Written commitments covering DFARS 252.204-7012 paragraphs (c) through (g), including notice, preservation, malware, forensic, and damage-assessment support.
What your company decides: How your 72-hour reporting process works with Egnyte's notice and evidence.
Basis: DFARS 252.204-7012(b)(2)(ii)(D), (c)-(g); DoD equivalency memorandum.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
10. Who can reach the data
Ask Egnyte for: Access-eligibility rules for administrators, support, engineering, and subprocessors; storage and support locations; access logs; and key-management roles.
What your company decides: Whether the answer fits the CUI category and any export-control or contract restriction that applies to your data.
Basis: Your contract, export-control analysis, SSP, and data flow.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
11. Work outside the subscription
Ask Egnyte for: A written split of endpoint management, identity, email, training, monitoring, incident response, SSP maintenance, and evidence operations: what Egnyte does, what is bundled, and what remains yours.
What your company decides: Who owns each remaining task: internal staff, another provider, or genuinely included work.
Basis: Your assessment boundary, CRM, SSP, and service order.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
12. Exit and records
Ask Egnyte for: Export formats, access after cancellation, deletion terms, transition assistance, retained-access period, and all charges.
What your company decides: How you retain required assessment artifacts and operational records without depending on an expired subscription.
Basis: §170.16(c)(4); your contract and quote.
Record fields:
Status: Unknown
Status:
Owner:
Evidence requested:
Evidence reference and review date:
Unresolved issue:
Next action:
Reason, if not applicable:
STATUS DEFINITIONS
Unknown | Nobody has asked or answered yet. This is the default.
Requested | You asked Egnyte or your team, and you are waiting.
Reviewed | Someone qualified read the material. This is not a CMMC determination.
Not applicable | Allowed only with a written reason.
WARNINGS
Keep evidence in your company's approved systems.
Do not place CUI, drawings, credentials, or sensitive contract details in this worksheet.
'Reviewed' is not a CMMC determination.
SOURCES
- FedRAMP Marketplace, "EgnyteGov," package FR2024952734 — https://www.fedramp.gov/marketplace/products/FR2024952734/ (checked September 24, 2026)
- 32 CFR 170.16, Level 2 self-assessment, SPRS, affirmation, cloud, and artifact-retention requirements — https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.16 (checked September 24, 2026; eCFR displayed current through September 23, 2026)
- 32 CFR 170.19, CMMC scoping, Level 2 asset categories, CSP/ESP treatment, and VDI condition — https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.19 (checked September 24, 2026)
- DFARS 252.204-7012 (MAY 2024), paragraphs (b)(2)(ii)(D), (c)-(g), and (m) — https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. (checked September 24, 2026)
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems — https://www.acquisition.gov/far/52.204-21 (checked September 24, 2026)
- DoW CIO, "About CMMC" — https://dowcio.war.gov/CMMC/About/ (checked September 24, 2026)
- Under Secretary of War for Acquisition and Sustainment, "Implementing Department of War Chief Information Officer's Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements," memorandum 26-P-1023 and Attachment 1, July 13, 2026 — https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf (read in full September 24, 2026)
- Defense Acquisition Regulations System, DFARS Revolutionary FAR Overhaul Class Deviations — https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html (index checked September 24, 2026; listed 2026-O0025 Revision 3 dated September 3, 2026; attachment not represented as read)
- DoD CIO, "FedRAMP Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings," December 21, 2023 — https://dowcio.war.gov/Portals/0/Documents/Library/FEDRAMP-EquivalencyCloudServiceProviders.pdf (read in full September 24, 2026)
- NIST SP 800-171 Revision 2, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations" — https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final (checked September 24, 2026; CMMC applicability verified against 32 CFR Part 170)
- NIST SP 800-171A June 2018, "Assessing Security Requirements for Controlled Unclassified Information" — https://csrc.nist.gov/pubs/sp/800/171/a/final (checked September 24, 2026; CMMC applicability verified against 32 CFR 170.16)
- NIST CMVP, FIPS 140-3 Transition Effort — https://csrc.nist.gov/projects/fips-140-3-transition-effort (checked September 24, 2026)
- U.S. Department of Commerce, Bureau of Industry and Security, "What is a deemed export?" — https://www.bis.gov/learn-support/deemed-exports/what-deemed-export (checked September 24, 2026)
- Egnyte, "Egnyte Achieves FedRAMP Moderate Equivalency and Marketplace Listing," July 22, 2025 — https://www.egnyte.com/press-releases/egnyte-achieves-fedramp-moderate-equivalency-and-marketplace-listing-strengthening-secure-cloud-collaboration-for-the-public-sector (checked September 24, 2026; company statement)
- Egnyte blog, "Unlocking Enhanced Security: What Egnyte's FedRAMP Moderate Equivalency Means for You," July 30, 2025 — https://www.egnyte.com/blog/post/unlocking-enhanced-security-what-egnytes-fedramp-moderate-equivalency-means-for-you (checked September 24, 2026; company statement)
- Egnyte blog, "Egnyte's Journey to FedRAMP Compliance and Beyond," August 15, 2025 — https://www.egnyte.com/blog/post/egnytes-journey-to-fedramp-compliance-and-beyond (checked September 24, 2026; company statement)
- Egnyte, CMMC Compliance product page — https://www.egnyte.com/products/cmmc-compliance (checked September 24, 2026; company claims)
- Egnyte, Pricing — https://www.egnyte.com/pricing (checked September 24, 2026)
- Egnyte, Compliance Standards — https://www.egnyte.com/security/compliance-standards (checked September 24, 2026; company claims)
- Egnyte, AI-powered workflow automation release, August 5, 2026 — https://www.egnyte.com/press-releases/egnyte-launches-ai-powered-workflow-automation-with-built-in-governance-to-help-organizations-scale-efficiently-and-securely (checked September 24, 2026; company claims)
- Egnyte Help Center, "CMMC 2.0 Resources for DoD Contractors and Subcontractors" — https://helpdesk.egnyte.com/hc/en-us/articles/28498075928589-CMMC-2-0-Resources-for-DoD-Contractors-and-Subcontractors (checked September 24, 2026; offering names only; timing language not relied on)
- Egnyte Help Center, "Microsoft 365 FAQs" — https://helpdesk.egnyte.com/hc/en-us/articles/360026902251-Microsoft-365-FAQs (checked September 24, 2026; does not establish EgnyteGov availability)
- Egnyte, ERRG case study — https://www.egnyte.com/customers/errg-case-study (checked September 24, 2026; company-stated customer story)
Keep the actual evidence in your company's approved systems. Do not put CUI, drawings, credentials, or sensitive contract details in the worksheet.
What should an Egnyte CMMC quote include?
A license quote does not describe the whole project. Separate the platform from setup, ongoing work, and any assessment. Then you can compare proposals without counting bundled work twice.
Start with what is public. On September 24, 2026, Egnyte's pricing page listed its commercial plans at $22, $39, and $48 per user per month, billed annually, with Ultimate quote-only. We found no public EgnyteGov price, so do not budget from the commercial numbers.
| Cost bucket | Unit and period | What the quote must show |
|---|---|---|
| Internal setup effort | Staff hours for the project; add an internal hourly rate only if you want a dollar view. | Discovery, decisions, testing, policies, training, and evidence; do not count hours already included in another bucket. |
| Internal ongoing effort | Staff hours per month, shown over the same 12 months. | Access reviews, evidence review, administration, incident exercises, and changes. |
| Implementation and migration | One-time project price in U.S. dollars. | Deliverables, data moved, configuration, acceptance tests, dependencies, and exclusions. |
| Platform and add-ons | U.S. dollars over the same 12 months. | Exact offering, license count, minimums, storage or usage charges, support, term, and renewal basis. |
| Outside ongoing operations | U.S. dollars over the same 12 months. | Endpoint, identity, security administration, monitoring, and incident support; identify anything bundled elsewhere. |
| Readiness help | Separately scoped project price. | Scope, documentation, remediation support, evidence work, and exact deliverables. |
| Formal assessment, only after the current written requirement is confirmed | A separate quote for the assessment path the contracting officer confirms applies. | During the suspension, current DoW direction permits only Level 1 (Self) and Level 2 (Self) designations and directs removal of Level 2 (C3PAO) and Level 3 requirements. Do not budget from stale solicitation or contract text without the amendment or modification. |
| Exit and records | One-time charges plus any paid retained-access period. | Export, deletion, transition help, evidence custody, and continued access. |
Leave unknown amounts blank and label them unquoted. A blank is not zero. For the wider budget, see our CMMC Level 2 cost guide and enclave cost guide.
A request you can send Egnyte today
Copy this, fill in the name, and send it before you sign or migrate.
Subject: EgnyteGov evidence and quote request
Hello [name],
We're evaluating EgnyteGov to store controlled unclassified information (CUI) under DFARS 252.204-7012 and a possible CMMC Level 2 requirement. Please answer in writing:
1. Will our CUI domain be on EgnyteGov, and which services, features, add-ons, support tiers, and exclusions does the quote include?
2. Which route covers that exact service: a FedRAMP Moderate-or-higher authorization, or the DoD FedRAMP Moderate-equivalency route?
3. Under a non-disclosure agreement, can we review the body of evidence, including the System Security Plan, Security Assessment Plan, Security Assessment Report and Risk Exposure Table, assessment-derived closure evidence, Plan of Action and Milestones and continuous-monitoring material? Please include the FedRAMP-recognized 3PAO's name, the assessment dates, and the latest annual 3PAO validation evidence.
4. Please send the current Customer Responsibility Matrix for every service and feature we would buy.
5. Which of these are inside the assessed EgnyteGov boundary: desktop app, Smart Cache or other local caching, mobile apps, Microsoft 365 or Google Workspace co-editing, the Outlook add-in, AI features, connectors, APIs, backups, and customer-supplied storage?
6. Where are files, versions, metadata, logs, backups, prompts, and AI outputs stored, processed, and supported?
7. What are the CMVP certificate numbers, module names, versions, operational environments, and configurations for cryptography protecting our data at rest and in transit? Is each certificate FIPS 140-3 Active or FIPS 140-2 Historical?
8. What will you commit to in writing under DFARS 252.204-7012 paragraphs (c) through (g): incident notice, malware support, 90-day preservation, forensic access, and damage-assessment support?
9. What access-eligibility rules apply to administrative, support, engineering, and subprocessor access to EgnyteGov customer data? Please include storage and support locations and access logging.
10. Who manages encryption keys, and which customer-managed-key options are included in this offering?
11. Will you notify us in writing if the equivalency status, body of evidence, service boundary, encryption modules, subprocessors, incident terms, or FedRAMP Marketplace status changes?
12. What can we export and retain if we cancel, in what formats, for how long, and at what cost?
For pricing, please separate the Egnyte offering and add-ons from implementation, migration, ongoing administration, readiness work, and any assessment work. For each line, list the quantity, term, inclusions, exclusions, dependencies, and responsible party.
Please do not send CUI in reply. We will establish an NDA and an approved secure channel before exchanging nonpublic evidence.
Subject: EgnyteGov evidence and quote request
Hello [name],
We're evaluating EgnyteGov to store controlled unclassified information (CUI) under DFARS 252.204-7012 and a possible CMMC Level 2 requirement. Please answer in writing:
- Will our CUI domain be on EgnyteGov, and which services, features, add-ons, support tiers, and exclusions does the quote include?
- Which route covers that exact service: a FedRAMP Moderate-or-higher authorization, or the DoD FedRAMP Moderate-equivalency route?
- Under a non-disclosure agreement, can we review the body of evidence, including the System Security Plan, Security Assessment Plan, Security Assessment Report and Risk Exposure Table, assessment-derived closure evidence, Plan of Action and Milestones and continuous-monitoring material? Please include the FedRAMP-recognized 3PAO's name, the assessment dates, and the latest annual 3PAO validation evidence.
- Please send the current Customer Responsibility Matrix for every service and feature we would buy.
- Which of these are inside the assessed EgnyteGov boundary: desktop app, Smart Cache or other local caching, mobile apps, Microsoft 365 or Google Workspace co-editing, the Outlook add-in, AI features, connectors, APIs, backups, and customer-supplied storage?
- Where are files, versions, metadata, logs, backups, prompts, and AI outputs stored, processed, and supported?
- What are the CMVP certificate numbers, module names, versions, operational environments, and configurations for cryptography protecting our data at rest and in transit? Is each certificate FIPS 140-3 Active or FIPS 140-2 Historical?
- What will you commit to in writing under DFARS 252.204-7012 paragraphs (c) through (g): incident notice, malware support, 90-day preservation, forensic access, and damage-assessment support?
- What access-eligibility rules apply to administrative, support, engineering, and subprocessor access to EgnyteGov customer data? Please include storage and support locations and access logging.
- Who manages encryption keys, and which customer-managed-key options are included in this offering?
- Will you notify us in writing if the equivalency status, body of evidence, service boundary, encryption modules, subprocessors, incident terms, or FedRAMP Marketplace status changes?
- What can we export and retain if we cancel, in what formats, for how long, and at what cost?
For pricing, please separate the Egnyte offering and add-ons from implementation, migration, ongoing administration, readiness work, and any assessment work. For each line, list the quantity, term, inclusions, exclusions, dependencies, and responsible party.
Please do not send CUI in reply. We will establish an NDA and an approved secure channel before exchanging nonpublic evidence.
When Egnyte fits, and when you need something else
EgnyteGov fits the job when CUI lives mostly in files and drawings, the exact quoted service holds up against the worksheet, and your team can keep the workflow inside the documented boundary. When the real gap is running the environment, organizing evidence, or handling CUI that lives in ordinary email and collaboration, a different kind of help may come first. These are this publication's judgments drawn from the facts above. They are not endorsements.
| Your situation | Evaluate next | Do not assume |
|---|---|---|
| You have confirmed FCI only, and Level 1 is required. | Whether your current tools meet the 15 Level 1 safeguards in our checklist. | That you need a CUI enclave. |
| CUI lives mostly in files and drawings, and your team already works in Egnyte. | EgnyteGov, using the worksheet above and a real workflow test. | That the product name makes the environment ready. |
| CUI arrives and lives mostly in email, chat, meetings, and shared files. | A broader government-cloud environment or an encrypted email-and-file workflow. Compare GCC High, PreVeil, and enclave versus GCC High. | That a file platform automatically covers email and collaboration. |
| Your drawings have export-control restrictions, and you cannot get a clear answer on people, locations, or access. | Options whose access eligibility, locations, support model, and export-control fit are documented in writing; see the ITAR guide. | That a FedRAMP record settles export-control eligibility. |
| You already have secure infrastructure, but evidence and ownership are a mess. | Readiness help or governance, risk, and compliance (GRC) software; start with the CMMC software guide. | That a second file platform fixes a program-management problem. |
| Nobody owns day-to-day endpoint and security operations. | A managed service provider (MSP) or managed security service provider (MSSP) with a written scope; see managed IT services for defense contractors. | That a file subscription includes operations. |
| Your solicitation or contract still says Level 2 (C3PAO) or Level 3 during the suspension. | Obtain the specific amendment or modification and contracting-officer confirmation first. Current DoW direction calls for those requirements to be removed; if a future written requirement restores the assessment path, keep formal assessment separate from readiness help and see RPO versus C3PAO. | That stale text disappears without written action—or that the suspended November 10, 2026 date or an Egnyte purchase creates a current C3PAO requirement. |
For the full comparison of file-sharing setups, see CMMC compliant file sharing. For every kind of help side by side, see CMMC provider categories.
You have probably found your row by now, or found yourself between two. The landing page for Find My CMMC Path says it asks about your contract, data, environment, timeline, and budget, then routes you toward a provider category rather than a named company. We verified that description on the landing page; we did not complete the interactive flow.
How we checked this guide
This is a public-source buyer guide, not a hands-on product test. We read the official FedRAMP record, the governing requirements, the current CMMC status pages, and Egnyte's public materials, and kept those kinds of evidence separate. Where the public record did not settle a buyer question, we turned it into an evidence request instead of an answer.
What we verified, and when:
- September 24, 2026: the EgnyteGov FedRAMP Marketplace record, including its September 22 status date.
- September 24, 2026: 32 CFR 170.16 and 170.19. The eCFR displayed Title 32 current through September 23, 2026.
- September 24, 2026: DFARS 252.204-7012 on Acquisition.gov, the current DoW CIO CMMC overview, the July 13 suspension release, and the full implementing memorandum and Attachment 1.
- September 24, 2026: the official DARS class-deviation index, which listed Class Deviation 2026-O0025, Revision 3, dated September 3, 2026. The linked attachment timed out and is not represented here as read.
- September 24, 2026: the full DoD CIO FedRAMP Moderate Equivalency memorandum, NIST SP 800-171 Revision 2, NIST SP 800-171A June 2018, and NIST's FIPS 140-3 transition page.
- September 24, 2026: Egnyte's CMMC product page, pricing page, compliance standards page, July 22, 2025 announcement, July 30 and August 15, 2025 blog posts, August 5, 2026 product release, relevant help-center pages, and the ERRG case study.
- September 24, 2026: the landing page for Find My CMMC Path. We verified its stated category-routing purpose but did not complete the flow.
What we could not verify from public material:
- The identity of Egnyte's FedRAMP-recognized 3PAO.
- The complete contents, exact current dates, findings, and boundary of Egnyte's private evidence package.
- The current CRM for any particular EgnyteGov order.
- Egnyte's CMVP certificate numbers and deployment mapping.
- Contractual support for DFARS 252.204-7012 paragraphs (c) through (g).
- Access-eligibility rules for EgnyteGov customer data, including whether particular roles are limited to U.S. persons.
- Which integrations, local-cache options, and AI features are inside a particular EgnyteGov assessed boundary.
- EgnyteGov pricing, implementation terms, or exit charges.
- Any customer's official CMMC assessment result.
- A public Reform Task Force report or replacement Phase II date on the current Department CMMC pages.
We did not test an Egnyte tenant, inspect the private package, review a customer quote or contract, or verify a customer outcome. The rule text says Department of Defense; current department webpages use Department of War. Our publication's commercial practices are described in the Editorial & Advertising Policy.
Frequently asked questions
We already put CUI in our commercial Egnyte. What now?
Stop adding more CUI to the unresolved environment, preserve relevant logs and records, identify what is already there, and map every copy, share, integration, and download. Move the information through an approved process into an environment whose exact cloud-security route and responsibilities you have documented. Whether the situation triggers a contract notice or cyber-incident report depends on the facts and the applicable clause; do not delete evidence or guess.
Does a virtual desktop keep our laptops out of scope?
Only under a narrow condition. 32 CFR 170.19(c)(1), Table 3 treats an endpoint running a virtual desktop infrastructure (VDI) client as out of scope only when the client allows no processing, storage, or transmission of CUI beyond keyboard, video, and mouse signals. An ordinary browser session with downloads disabled is not automatically the same thing.
A prime asked whether our Egnyte is "FedRAMP." What do we say?
Name the exact environment and separate the two claims. As of September 24, 2026, EgnyteGov package FR2024952734 was Agency Auth In Process with zero authorizations; Egnyte separately states that EgnyteGov achieved DoD FedRAMP Moderate equivalency. Do not call it FedRAMP Authorized. If your company has not reviewed the current body of evidence for the service it uses, say that plainly rather than saying you rely on equivalency.
Can subcontractors reach CUI we keep in EgnyteGov?
Egnyte supports outside sharing, but the authorization and contract questions remain yours. Confirm that the recipient and its environment are allowed to receive the information, control what lands on its devices, and use named, expiring access rather than open links. DFARS 252.204-7012 paragraph (m) requires flow-down when subcontract performance involves covered defense information or operationally critical support; see our flow-down guide.
What happens to our evidence if we cancel Egnyte?
Canceling does not cancel your record-retention duty. For a Level 2 self-assessment, 32 CFR 170.16(c)(4) requires the organization seeking assessment to keep the artifacts used as assessment evidence for six years from the CMMC Status Date. Confirm export formats, custody, access, and deletion terms before cancellation. That is check 12 on the worksheet.
Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.
Sources
- FedRAMP Marketplace, "EgnyteGov," package FR2024952734 — https://www.fedramp.gov/marketplace/products/FR2024952734/ (checked September 24, 2026)
- 32 CFR 170.16, Level 2 self-assessment, SPRS, affirmation, cloud, and artifact-retention requirements — https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.16 (checked September 24, 2026; eCFR displayed current through September 23, 2026)
- 32 CFR 170.19, CMMC scoping, Level 2 asset categories, CSP/ESP treatment, and VDI condition — https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.19 (checked September 24, 2026)
- DFARS 252.204-7012 (MAY 2024), paragraphs (b)(2)(ii)(D), (c)-(g), and (m) — https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. (checked September 24, 2026)
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems — https://www.acquisition.gov/far/52.204-21 (checked September 24, 2026)
- DoW CIO, "About CMMC" — https://dowcio.war.gov/CMMC/About/ (checked September 24, 2026)
- Under Secretary of War for Acquisition and Sustainment, "Implementing Department of War Chief Information Officer's Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements," memorandum 26-P-1023 and Attachment 1, July 13, 2026 — https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf (read in full September 24, 2026)
- Defense Acquisition Regulations System, DFARS Revolutionary FAR Overhaul Class Deviations — https://www.acq.osd.mil/dpap/dars/dfarsfaroverhaulclassdeviations.html (index checked September 24, 2026; listed 2026-O0025 Revision 3 dated September 3, 2026; attachment not represented as read)
- DoD CIO, "FedRAMP Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings," December 21, 2023 — https://dowcio.war.gov/Portals/0/Documents/Library/FEDRAMP-EquivalencyCloudServiceProviders.pdf (read in full September 24, 2026)
- NIST SP 800-171 Revision 2, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations" — https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final (checked September 24, 2026; CMMC applicability verified against 32 CFR Part 170)
- NIST SP 800-171A June 2018, "Assessing Security Requirements for Controlled Unclassified Information" — https://csrc.nist.gov/pubs/sp/800/171/a/final (checked September 24, 2026; CMMC applicability verified against 32 CFR 170.16)
- NIST CMVP, FIPS 140-3 Transition Effort — https://csrc.nist.gov/projects/fips-140-3-transition-effort (checked September 24, 2026)
- U.S. Department of Commerce, Bureau of Industry and Security, "What is a deemed export?" — https://www.bis.gov/learn-support/deemed-exports/what-deemed-export (checked September 24, 2026)
- Egnyte, "Egnyte Achieves FedRAMP Moderate Equivalency and Marketplace Listing," July 22, 2025 — https://www.egnyte.com/press-releases/egnyte-achieves-fedramp-moderate-equivalency-and-marketplace-listing-strengthening-secure-cloud-collaboration-for-the-public-sector (checked September 24, 2026; company statement)
- Egnyte blog, "Unlocking Enhanced Security: What Egnyte's FedRAMP Moderate Equivalency Means for You," July 30, 2025 — https://www.egnyte.com/blog/post/unlocking-enhanced-security-what-egnytes-fedramp-moderate-equivalency-means-for-you (checked September 24, 2026; company statement)
- Egnyte blog, "Egnyte's Journey to FedRAMP Compliance and Beyond," August 15, 2025 — https://www.egnyte.com/blog/post/egnytes-journey-to-fedramp-compliance-and-beyond (checked September 24, 2026; company statement)
- Egnyte, CMMC Compliance product page — https://www.egnyte.com/products/cmmc-compliance (checked September 24, 2026; company claims)
- Egnyte, Pricing — https://www.egnyte.com/pricing (checked September 24, 2026)
- Egnyte, Compliance Standards — https://www.egnyte.com/security/compliance-standards (checked September 24, 2026; company claims)
- Egnyte, AI-powered workflow automation release, August 5, 2026 — https://www.egnyte.com/press-releases/egnyte-launches-ai-powered-workflow-automation-with-built-in-governance-to-help-organizations-scale-efficiently-and-securely (checked September 24, 2026; company claims)
- Egnyte Help Center, "CMMC 2.0 Resources for DoD Contractors and Subcontractors" — https://helpdesk.egnyte.com/hc/en-us/articles/28498075928589-CMMC-2-0-Resources-for-DoD-Contractors-and-Subcontractors (checked September 24, 2026; offering names only; timing language not relied on)
- Egnyte Help Center, "Microsoft 365 FAQs" — https://helpdesk.egnyte.com/hc/en-us/articles/360026902251-Microsoft-365-FAQs (checked September 24, 2026; does not establish EgnyteGov availability)
- Egnyte, ERRG case study — https://www.egnyte.com/customers/errg-case-study (checked September 24, 2026; company-stated customer story)
About The Defense Compliance Report
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
We are not affiliated with the Cyber AB, the Department of Defense, the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC), NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney.